
EC-CouncilDevSecOps Essentials
Domain 6Objective 5
Integrating a Continuous Feedback Loop DSE Practice Questions (Page 8)
Part of the DevSecOps Monitoring and Feedback domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
Questions 36–40
- 36
A team wants to add a security feedback gate to their CI pipeline, but they are concerned about slowing down developers. They have a mix of high-risk and low-risk changes. What is the best way to balance security feedback with developer velocity?
Select an answer first - 37
A DevSecOps team wants to improve security posture by learning from past incidents and near-misses. They have implemented a feedback loop that collects data from incident reports, monitoring alerts, and post-mortems. What is the primary purpose of this continuous feedback loop?
Select an answer first - 38
A company has a DevSecOps pipeline that includes security scans, but the development team often bypasses the scans by pushing directly to the main branch. The security team wants to enforce the feedback loop, but the development team argues that the scans are too slow and block urgent fixes. What is the best way to resolve this conflict?
Select an answer first - 39
A DevSecOps team wants to measure the effectiveness of their continuous feedback loop. They have been tracking the number of vulnerabilities found in production, but the number has not changed over the past quarter. They suspect the feedback loop is not working. What is the most likely reason for this lack of improvement?
Select an answer first - 40
A company's CI/CD pipeline runs unit tests, SAST, and dependency scanning. The team notices that developers often ignore warnings from the dependency scanner because the pipeline still succeeds. They want to ensure that critical dependency vulnerabilities block the release. What is the most effective way to integrate this feedback into the pipeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.